Microsoft Defender for Identity offers real-time threat detection and protection for hybrid Active Directory environments. It integrates with Microsoft 365 components for seamless security and monitors advanced behaviors, enhancing identity protection across cloud and on-premises environments.
| Product | Market Share (%) |
|---|---|
| Microsoft Defender for Identity | 12.5% |
| CrowdStrike Falcon | 14.5% |
| Microsoft Entra ID Protection | 8.7% |
| Other | 64.3% |
| Type | Title | Date | |
|---|---|---|---|
| Category | Identity Threat Detection and Response (ITDR) | Dec 30, 2025 | Download |
| Product | Reviews, tips, and advice from real users | Dec 30, 2025 | Download |
| Comparison | Microsoft Defender for Identity vs CrowdStrike Falcon | Dec 30, 2025 | Download |
| Comparison | Microsoft Defender for Identity vs Microsoft Entra ID Protection | Dec 30, 2025 | Download |
| Comparison | Microsoft Defender for Identity vs Varonis Platform | Dec 30, 2025 | Download |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| CrowdStrike Falcon | 4.3 | 14.5% | 97% | 136 interviewsAdd to research |
| Microsoft Intune | 4.1 | N/A | 94% | 305 interviewsAdd to research |
| Company Size | Count |
|---|---|
| Small Business | 7 |
| Midsize Enterprise | 4 |
| Large Enterprise | 14 |
| Company Size | Count |
|---|---|
| Small Business | 305 |
| Midsize Enterprise | 142 |
| Large Enterprise | 609 |
Microsoft Defender for Identity provides detailed threat insights and user behavior analytics to detect unauthorized access and notify anomalies. It allows setting custom detection rules, enhancing threat response automation. While it needs improvements in cloud security, SIEM integration, and access controls, users leverage its ability to mitigate identity threats like suspicious logins and ransomware. Enhanced integration with Microsoft security products ensures a coordinated threat response for identity control and privilege management.
What are the key features of Microsoft Defender for Identity?In specific industries, organizations implement Microsoft Defender for Identity to secure on-premises and hybrid Active Directory environments through user and entity behavior analytics, malicious activity detection, and integration with Microsoft security tools. This approach enhances security posture assessment and helps mitigate identity threats like identity harvesting and unauthorized access.
Microsoft Defender for Identity was previously known as Azure Advanced Threat Protection, Azure ATP, MS Defender for Identity.
Microsoft Defender for Identity is trusted by companies such as St. Luke’s University Health Network, Ansell, and more.
| Author info | Rating | Review Summary |
|---|---|---|
| Cloud Security & Governance at a financial services firm with 10,001+ employees | 4.0 | We use Microsoft Defender for Identity to protect our on-premises and hybrid Active Directory, focusing on advanced threat detection and security posture assessment. Despite its strengths, reducing alert fatigue remains necessary as we enhance integration with Azure AD. |
| CyberSecurity Engineer | Information Security Management at Self Employed | 5.0 | I find Microsoft Defender for Identity valuable for its conditional access and role-based permissions. It saves time but could improve in automation for impossible travel detection, particularly with VPNs, to reduce unnecessary disruptions and enhance security. |
| Instrumentation Engineer at Toyo Engineering Corp | 4.0 | We're testing Microsoft Defender for Identity, which auto-remediates incidents, saving investigation time and offering preemptive security. It identifies and mitigates threats from different IPs efficiently. We're in the initial phase, using it alongside Microsoft Azure. |
| Security Engineer at Fidelity Bank Plc | 4.0 | I've used Microsoft Defender for Identity in a hybrid setup with Azure AD for over five years; it's effective but costly, has occasional latency, limited third-party integration, and setup requires ongoing optimization despite responsive technical support. |
| Technology Coordinator at a educational organization with 501-1,000 employees | 4.0 | I've used Microsoft Defender for Identity for years; it saves me time, improves threat visibility, and supports faster responses, though I don’t use it much lately. It's stable, effective, and customer support has been knowledgeable and efficient. |
| Manager, Collaboration Bds at C3ntro | 5.0 | I've used Microsoft Defender for Identity for four years; it's stable, helps secure data, and fits our financial clients well. While not time- or cost-saving for me, it's essential to our enterprise security services. |
| CTO at a tech vendor with 10,001+ employees | 4.0 | I use Microsoft Defender for Identity as part of the Defender suite to manage identities. Its seamless integration with other tools is valuable, though it’s expensive with Sentinel and could improve integration with non-Microsoft systems. No ROI seen yet. |
| Deputy Manager at Servion Global Solutions | 5.0 | I’ve used Microsoft Defender for Identity for over four years, and it’s stable, scalable, and effective with valuable threat analytics and reporting. Setup was smooth with support from Microsoft's fast track team, and I have no complaints. |